Please report security issues via GitHub Issues using the Security Report template. Do not open public issues for undisclosed vulnerabilities.
The 8-point security scanner uses pattern matching and heuristics. It cannot guarantee a skill is safe. Always review skills before installing with --force.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
- Do not publish secrets in SKILL.md files
- Run
skillreg auditperiodically on installed skills - Use
--forceonly when you trust the skill source